thinksaas kayıtları
thinksaas üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-35337İstismar yok | ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows thinksaas · thinksaas · CWE-89 | Kritik9,8 | — | %1,9 | 24 Mar 2021 |
39İzleyin | CVE-2024-40456İstismar yok | ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.thinksaas · thinksaas · CWE-89 | Kritik9,8 | — | %0,5 | 16 Tem 2024 |
24İzleyin | CVE-2019-16665İstismar yok | An issue was discovered in ThinkSAAS 2.91.thinksaas · thinksaas · CWE-79 | Orta6,1 | — | %0,7 | 21 Eyl 2019 |
24İzleyin | CVE-2024-33101İstismar yok | A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrarthinksaas · thinksaas · CWE-79 | Orta6,1 | — | %0,4 | 30 Nis 2024 |
21İzleyin | CVE-2020-18741İstismar yok | Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "thinksaas · thinksaas | Orta5,3 | — | %0,9 | 8 Tem 2021 |
21İzleyin | CVE-2018-15129İstismar yok | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.thinksaas · thinksaas · CWE-79 | Orta5,4 | — | %0,7 | 7 Ağu 2018 |
21İzleyin | CVE-2018-15130İstismar yok | ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.thinksaas · thinksaas · CWE-79 | Orta5,4 | — | %0,7 | 7 Ağu 2018 |
21İzleyin | CVE-2024-6941İstismar yok | ThinkSAAS do.php cross site scriptingthinksaas · thinksaas · CWE-79 | Orta5,3 | — | %0,4 | 21 Tem 2024 |
21İzleyin | CVE-2024-6942İstismar yok | ThinkSAAS Admin Panel Security Center anti.php cross site scriptingthinksaas · thinksaas · CWE-79 | Orta5,3 | — | %0,4 | 21 Tem 2024 |
21İzleyin | CVE-2024-33102İstismar yok | A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrathinksaas · thinksaas · CWE-79 | Orta5,4 | — | %0,4 | 30 Nis 2024 |
19İzleyin | CVE-2019-16664İstismar yok | An issue was discovered in ThinkSAAS 2.91.thinksaas · thinksaas · CWE-79 | Orta4,8 | — | %0,6 | 21 Eyl 2019 |
10İzleyin | CVE-2024-40455İstismar yok | An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.thinksaas · thinksaas · CWE-352 | Düşük2,7 | — | %0,2 | 16 Tem 2024 |
- CVE-2020-3533740Planlayın
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows
KritikCVSS 9,8İstismar yokEPSS %2thinksaas · thinksaas24 Mar 2021
- CVE-2024-4045639İzleyin
ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.
KritikCVSS 9,8İstismar yokEPSS %1thinksaas · thinksaas16 Tem 2024
- CVE-2019-1666524İzleyin
An issue was discovered in ThinkSAAS 2.91.
OrtaCVSS 6,1İstismar yokEPSS %1thinksaas · thinksaas21 Eyl 2019
- CVE-2024-3310124İzleyin
A stored cross-site scripting (XSS) vulnerability in the component /action/anti.php of ThinkSAAS v3.7.0 allows attackers to execute arbitrar
OrtaCVSS 6,1İstismar yokEPSS %0thinksaas · thinksaas30 Nis 2024
- CVE-2020-1874121İzleyin
Improper Authorization in ThinkSAAS v2.7 allows remote attackers to modify the description of any user's photo via the "photoid%5B%5D" and "
OrtaCVSS 5,3İstismar yokEPSS %1thinksaas · thinksaas8 Tem 2021
- CVE-2018-1512921İzleyin
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
OrtaCVSS 5,4İstismar yokEPSS %1thinksaas · thinksaas7 Ağu 2018
- CVE-2018-1513021İzleyin
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
OrtaCVSS 5,4İstismar yokEPSS %1thinksaas · thinksaas7 Ağu 2018
- CVE-2024-694121İzleyin
ThinkSAAS do.php cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0thinksaas · thinksaas21 Tem 2024
- CVE-2024-694221İzleyin
ThinkSAAS Admin Panel Security Center anti.php cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0thinksaas · thinksaas21 Tem 2024
- CVE-2024-3310221İzleyin
A stored cross-site scripting (XSS) vulnerability in the component /pubs/counter.php of ThinkSAAS v3.7.0 allows attackers to execute arbitra
OrtaCVSS 5,4İstismar yokEPSS %0thinksaas · thinksaas30 Nis 2024
- CVE-2019-1666419İzleyin
An issue was discovered in ThinkSAAS 2.91.
OrtaCVSS 4,8İstismar yokEPSS %1thinksaas · thinksaas21 Eyl 2019
- CVE-2024-4045510İzleyin
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.
DüşükCVSS 2,7İstismar yokEPSS %0thinksaas · thinksaas16 Tem 2024